URL:
  <https://savannah.gnu.org/bugs/?68710>

                 Summary: :dinfo causes crash on macOS
                   Group: GNU Screen
               Submitter: None
               Submitted: Mon 21 Sep 2026 08:02:58 PM UTC
                Category: Crash/Freeze/Infloop
                Severity: 3 - Normal
                Priority: 5 - Normal
                  Status: None
                 Privacy: Public
             Assigned to: None
             Open/Closed: Open
         Discussion Lock: Unlocked
                 Release: 5.0.2
           Fixed Release: None
         Planned Release: None
           Work Required: None


    _______________________________________________________

Follow-up Comments:


-------------------------------------------------------
Date: Mon 21 Sep 2026 08:02:58 PM UTC By: Anonymous
I'm seeing a crash on macOS when I invoke :dinfo. The ASan report is as
follows:


=================================================================
==15398==ERROR: AddressSanitizer: stack-buffer-overflow on address
0x00016b942520 at pc 0x000104fd31b0 bp 0x00016b9422f0 sp 0x00016b941aa0
WRITE of size 504 at 0x00016b942520 thread T0
    #0 0x000104fd31ac in strncpy+0x414
(libclang_rt.asan_osx_dynamic.dylib:arm64e+0x3b1ac)
    #1 0x000104545e78 in DoCommandDinfo process.c:1594
    #2 0x00010453ccac in DoAction process.c:4823
    #3 0x00010456695c in DoCommand process.c:5318
    #4 0x000104511518 in RcLine fileio.c:308
    #5 0x00010456cae0 in ColonFin process.c
    #6 0x00010451a22c in InpProcess input.c:373
    #7 0x00010453b560 in ProcessInput2 process.c:745
    #8 0x000104508dc8 in disp_processinput display.c:2796
    #9 0x0001044e86f0 in disp_readev_fn display.c:2770
    #10 0x000104576044 in sched sched.c:200
    #11 0x0001044bc7f8 in main screen.c:1107
    #12 0x00019ef03e7c in start+0x1a1c (dyld:arm64e+0x31e7c)

Address 0x00016b942520 is located in stack of thread T0 at offset 544 in
frame
    #0 0x000104545cd0 in DoCommandDinfo process.c:1591

  This frame has 1 object(s):
    [32, 544) 'buf' (line 6270) <== Memory access at offset 544 overflows this
variable
HINT: this may be a false positive if your program uses some custom stack
unwind mechanism, swapcontext or vfork
      (longjmp and C++ exceptions *are* supported)
SUMMARY: AddressSanitizer: stack-buffer-overflow process.c:1594 in
DoCommandDinfo
Shadow bytes around the buggy address:
  0x00016b942280: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x00016b942300: f1 f1 f1 f1 00 00 00 00 00 00 00 00 00 00 00 00
  0x00016b942380: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x00016b942400: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x00016b942480: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
=>0x00016b942500: 00 00 00 00[f3]f3 f3 f3 f3 f3 f3 f3 00 00 00 00
  0x00016b942580: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x00016b942600: f1 f1 f1 f1 f8 f2 f8 f2 f2 f2 f8 f2 f2 f2 f8 f2
  0x00016b942680: f8 f2 f2 f2 f8 f3 f3 f3 00 00 00 00 00 00 00 00
  0x00016b942700: 00 00 00 00 00 00 00 00 00 00 00 00 f1 f1 f1 f1
  0x00016b942780: 00 00 00 00 f3 f3 f3 f3 00 00 00 00 00 00 00 00
Shadow byte legend (one shadow byte represents 8 application bytes):
  Addressable:           00
  Partially addressable: 01 02 03 04 05 06 07 
  Heap left redzone:       fa
  Freed heap region:       fd
  Stack left redzone:      f1
  Stack mid redzone:       f2
  Stack right redzone:     f3
  Stack after return:      f5
  Stack use after scope:   f8
  Global redzone:          f9
  Global init order:       f6
  Poisoned by user:        f7
  Container overflow:      fc
  Array cookie:            ac
  Intra object redzone:    bb
  ASan internal:           fe
  Left alloca redzone:     ca
  Right alloca redzone:    cb
==15398==ABORTING


While I'm no C expert, I believe the attached patch resolves the issue. The
issue seems to be that *p++ = ' ' consumes one byte of of space without
decrementing l. So the code hands strncpy a limit that's 1 byte larger than
the space actually available.






    _______________________________________________________
File Attachments:

Name: fix-dinfo-offbyone.patch       Size: 289B

<https://file.savannah.gnu.org/file/fix-dinfo-offbyone.patch?file_id=58984>



    AGPL NOTICE

These attachments are served by Savane. You can download the corresponding
source code of Savane at
https://savannah.gnu.org/source/savane-1405920ddbd92feb15f7ff51a95593e5d679909d.tar.gz

    _______________________________________________________

Reply to this item at:

  <https://savannah.gnu.org/bugs/?68710>

_______________________________________________
Message sent via Savannah
https://savannah.gnu.org/

Attachment: signature.asc
Description: PGP signature

Reply via email to